Get written answers to five questions before you sign. Does it do your task on your own files, shown live? Is your data used to train any model? How long is it kept, and who receives it? How does the price grow with usage and at renewal? How do you get everything out? Vague answers are a reason to wait.
Below, the full set of questions is sorted by when to ask them: in an email before the demo, while the product is on screen, and when the contract arrives. Each comes with what a good answer and a walk-away answer sound like. There's an email you can send today and a scoring sheet for comparing two vendors side by side.
Why every answer should end up in writing
A sales call produces reassurance. The contract, the order form and the vendor's published terms decide what you actually get. If a salesperson says "we never train on customer data" but the terms allow your content to be used "for product improvement", the terms win.
So ask most questions by email, keep the replies, and for anything that matters (data use, price caps, exit rights) ask for the answer to be reflected in the order form or a signed side letter. Vendors selling to small businesses often use standard terms they won't change, which is fine. You still learn what you're agreeing to, and you can choose a different vendor if the standard terms don't fit.
The email to send before the demo
Send this at least a week before the demo. It does two jobs: it gets the data and pricing questions answered by someone who has to be accurate in writing, and it makes the demo run on your own material rather than the vendor's polished sample.
Subject: Questions before our demo on [date]
Hi [name],
Ahead of the demo, could you answer the questions below in writing?
We'll use the answers to compare vendors.
About the demo
1. Please run the demo on the three sample files attached
(identifying details removed). We want to see the output
on our material, not a prepared example.
About our data
2. Is any of our content (prompts, files, outputs) used to train
or improve any AI model, yours or a third party's? Where do
your terms say so?
3. How many days do you keep our inputs and outputs? Can we
shorten that?
4. Which other companies process our data for you? Please send
your current sub-processor list.
5. Will you sign a data processing agreement?
About cost
6. What is the unit you charge by (seat, credit, conversation,
task) and what happens when we go over our allowance?
7. What would we pay at double our expected volume?
8. How much can the price rise at renewal, and is that capped
in the contract?
About leaving
9. In what format can we export all our data, including
history and settings, and is export self-service?
10. After we cancel, when is our data deleted, and do you
confirm deletion in writing?
Thanks,
[your name]
Give them five working days. A vendor that can't answer ten written questions in a week is telling you something about how support tickets will feel after you've paid.
The replies tend to mix straight answers with marketing copy. Here is an illustrative reply of the kind small vendors often send, with the gaps marked in the way I'd mark them before replying:
2. "We take your privacy extremely seriously and never
sell your data."
-> Not an answer. Selling and training are different
things. Ask again, quoting the original question.
3. "Data is retained in line with our retention policy."
-> No number. Ask: "How many days, and which document
says so?"
4. "Our sub-processors include leading cloud providers."
-> Ask for the list itself and the date it was last
updated.
7. "Our Growth plan scales with your business."
-> Not a price. Ask for the monthly total at 1,000
conversations, overage included.
9. "Yes, CSV export is available."
-> A real answer. Ask what the CSV contains before
you rely on it (see the exit questions below).
A follow-up that usually works: "Thanks. For questions 2, 3, 4 and 7, could you give a yes or no, or a number, and point to the clause in your terms?" A vendor that dodges the same question twice has answered it.
Questions to ask while the product is on screen
A demo is a performance, and it's built to show the product at its best. These questions turn it into a test. The step-by-step method for running an AI software demo so you see the real product goes further; the table covers the questions that do most of the work.
| Ask | A good answer | A walk-away answer |
|---|---|---|
| Can you run it now on the files we sent? | Yes, live, including the awkward one | "Our demo environment only works with sample data" |
| What does it do when it isn't sure? | Shows a confidence flag or its sources, or passes the item to a person | "It's highly accurate", with no mechanism shown |
| Which AI model runs underneath, and who provides it? | Names the provider and model, and explains what happens when the provider updates it | "Our proprietary AI", with nothing more specific |
| Show me how someone corrects or overrides an output | An edit or approve step in the screen you just saw, with a record of the change | "Raise a ticket and we'll retrain it" |
| Which of the features shown are live on the plan you'd quote me? | A clear list, matching the quote | "That's on the roadmap" or "that's our enterprise tier" |
| What would I see in the log if something went wrong last Tuesday? | Who ran what, the input, the output and the time | No customer-visible logs |
| Can I speak to a customer of our size using this feature? | An introduction within a week | No references at all, or only much larger firms |
The model question matters more than it looks. Plenty of good tools are built on OpenAI, Anthropic or Google models, and that's not a problem in itself. You need to know because the underlying provider's terms and outages become your terms and outages. How to tell if a tool is a ChatGPT wrapper explains what that means for price and lock-in.
Data questions to settle before anything is uploaded
Most of these are answered, one way or another, in the vendor's privacy policy, terms and data processing agreement. Asking directly saves you hours and tests whether the salesperson's version matches the documents. For how to check the documents yourself, see what to check in an AI tool's privacy policy and terms.
- Is our content used to train or improve any model? Good: "No, by default, and here's the clause." Watch for a vendor that promises it doesn't train on your content while its terms let its AI provider do so, and for vague purposes such as "service improvement", which can include training.
- How long do you keep inputs and outputs? Good: a number of days, and a setting to shorten it. "As long as necessary" is not a number.
- Can your staff, or your provider's staff, read our content? Limited access for safety checks or support tickets is standard; what you need to know is when it happens, who can do it, and whether it's logged.
- Who are your sub-processors, and how much notice do you give before adding one? A sub-processor is another company that handles your data on the vendor's behalf, such as its cloud host or AI model provider. Good: a published list and a notice period with the right to object.
- Which regions is our data stored and processed in, and can we choose? Matters if your clients' contracts or data-protection law restrict where their data goes. Check with your adviser if you're unsure whether it applies to you.
- Will you sign a data processing agreement? If the tool touches personal data about customers or staff, you'll usually need one. A vendor that has never heard the term is not ready for business customers.
- How quickly will you tell us about a breach? Good: a specific number of hours written into the agreement, and a named contact route.
- Do you support single sign-on and two-factor authentication, and can we remove a leaver's access in one place? Offboarding is easy to get wrong in a small firm. You want one switch, not ten.
- Which independent security reports can we see? A SOC 2 Type II report is tested over a period of months rather than on a single day, so it says more than Type I. ISO/IEC 27001 certifies an information security management system. ISO/IEC 42001, published in December 2023, covers how an organisation manages AI specifically; it's newer, so fewer vendors hold it. Request the report or certificate itself, and check its date and what it covers; the plain-English guide to SOC 2 and ISO 27001 explains what to look for in each.
How the bill grows: pricing questions most buyers skip
Price pages show the starting number. These questions find the number you'll actually pay in month nine.
- What exactly is the unit? Seat, credit, conversation, "resolution", task or document. Then: what happens when we go over? Blocked, slowed down, or charged per unit? Get the overage rate in writing.
- What would we pay at twice our current volume? Ask them to price it. A tool that's cheap at 200 conversations a month can be expensive at 2,000, and your volume will move.
- Was the demo on the plan you're quoting? Demos often run on the top tier. Get the quote to list the features included, not just the plan name.
- Is there a minimum number of seats or a minimum term? Several business AI plans need at least two seats, and some quotes quietly assume twelve months.
- Is this a first-year or promotional price? Ask for the year-two price in the same email. Heavy first-year discounts are common in software.
- How much can the price rise at renewal? Good: a cap written into the contract, such as a fixed percentage. Without one, you negotiate renewal after your data and habits are already inside their system.
- Does it auto-renew, and what's the notice period? Put the notice date in your calendar the day you sign. The details of auto-renewals, price rises and notice periods are worth ten minutes before any annual commitment.
- What's charged separately? Onboarding, integrations, extra storage, premium support and API access are common add-ons.
Question 2 is easiest to see with a real price list. HubSpot charges for its Customer Agent in HubSpot Credits: 50 credits per resolved conversation, with credits at $10 per 1,000, so about $0.50 each time the agent closes an enquiry. A business expecting 400 resolved conversations a month needs about 20,000 credits, roughly $200 a month at list price before any credits its plan includes (500 a month on Starter, 3,000 on Professional, neither rolling over). At twice the volume the figure is about $400. None of that shows up in the headline seat price. Every usage-priced tool has an equivalent sum, so ask the vendor to do it on paper for your volume and for double it.
Exit questions to ask while the vendor still needs your signature
Before you sign, the vendor wants your business and will answer these carefully. A year in, your prompts, history and workflows live in their system and the conversation is harder.
- In what format can we export everything? Good: self-service export of data, conversation history, documents and settings in standard formats such as CSV, JSON or PDF. Walk-away: "export on request", with a fee, or no export of configuration at all.
- Can we export the prompts, instructions and workflows we build? These are often the most valuable thing you create, and the first thing people forget. Keeping your data and prompts portable covers how to hold copies from day one.
- After we cancel, when is our data deleted, and will you confirm it? Good: a set number of days and a written confirmation on request.
- What happens to our data and service if you're acquired or close down? Good: notice, an export window and deletion commitments that survive a sale.
- If your AI provider withdraws the model you use, what changes for us? Good: they test the replacement and tell you in advance. Walk-away: they didn't know this happens.
"CSV export available" can still leave you short. Consider an illustrative interior design studio that spent fourteen months in an AI proposal tool, building 30 saved prompt templates, a style guide and a library of room descriptions. When it moved, the export turned out to be a CSV of past proposals: title, client, date and the final text. The templates, the style guide and the tone settings weren't in it, and someone spent two afternoons copying them out by hand. The fix costs nothing if you do it early: during the trial, create one template and one setting, press export, and open the file to see whether they come out.
When the AI gets it wrong: who carries the cost?
AI output will sometimes be wrong. The contract decides whether that's your problem alone.
- What's the liability cap, and does it cover errors in AI output? Software contracts usually cap the vendor's liability, often by reference to the fees you've paid over a set period. Read the actual figure and any exclusions for AI-generated content.
- Do you offer a copyright indemnity for outputs? An indemnity is a promise to cover your costs if a third party sues. OpenAI's Copyright Shield, for example, was announced for ChatGPT Enterprise and API customers, not free users; check the current terms for the plan you'd buy. Don't assume a smaller tool built on top of a big provider's model passes that protection on to you; ask.
- What are your support hours and response times, in writing? "Email support" with no stated response time means whenever they get to it.
- If the tool gives one of our customers wrong information, what do you provide? Good: logs you can export and someone to call.
Put a number on the cap before you rely on it. Suppose the clause limits liability to "the fees paid by Customer in the twelve months preceding the claim", and you pay $150 a month: the most you could recover is $1,800. If the tool's chatbot quotes the wrong delivery charge on 60 orders and you honour the price, or it promises a refund your policy doesn't allow, that $1,800 is the ceiling. And if the terms also say the vendor "makes no warranty as to the accuracy of AI-generated output", the realistic figure may be nothing. That's normal in software, which is why the review step on your side matters more than the contract.
If the contract is large relative to your business, runs for more than a year, or covers health, financial or children's data, have a solicitor read it before you sign. The questions above tell you where to point them.
Score two vendors side by side
Score each answer 0 (no answer, vague, or verbal only), 1 (partial, or answered but not in the contract) or 2 (clear, and in writing). Four questions are must-pass: a 0 on any of them stops the purchase, however good the rest looks.
VENDOR SCORING SHEET Vendor: __________ Date: ______
MUST-PASS (a 0 on any stops the purchase)
[ ] Our content is not used for training by default 0 1 2
[ ] Full self-service export in a standard format 0 1 2
[ ] Breach notification time stated in the agreement 0 1 2
[ ] Renewal price rise capped or fixed 0 1 2
DEMO DATA COST
Ran on our files 0 1 2 Retention in days 0 1 2 Unit clear 0 1 2
Handles uncertainty 0 1 2 Staff access rules 0 1 2 Price at 2x 0 1 2
Model named 0 1 2 Sub-processor list 0 1 2 Features match 0 1 2
Human override 0 1 2 Signs a DPA 0 1 2 Year-two price 0 1 2
Logs available 0 1 2 SSO / 2FA 0 1 2 Extras listed 0 1 2
Reference offered 0 1 2 Security report 0 1 2
EXIT / LIABILITY
Prompts exportable 0 1 2 Deletion confirmed 0 1 2 Liability read 0 1 2
Support times 0 1 2
TOTAL: ____ / 50 Must-pass all 1 or above? Yes / No
Illustration: say a nine-person lettings agency is choosing between two tools that answer tenant enquiries out of hours. Vendor A gives the slicker demo but won't run it on the agency's own enquiry emails, describes its model as proprietary, and offers export "on request". Vendor B's demo is plainer, but it runs on the agency's real emails, names its model provider, publishes its sub-processors and exports conversation history as CSV.
Vendor A scores 27 out of 50 and fails the export must-pass. Vendor B scores 38 and passes all four, but only just on renewal: the salesperson said increases are "normally modest", and nothing in the contract says so, which scores 1. The agency picks B and uses the moment before signing, when it has the most bargaining power, to ask for a renewal cap in the order form. Whatever the vendor says, the agency now knows exactly what it's agreeing to.
That's the aim of the whole exercise: to sign with your eyes open, with the promises that matter written down and a way out if the tool doesn't earn its place.
Further reads
- How to Evaluate an AI Software Vendor: A Small Business Scorecard — A fuller scorecard once you've narrowed the field to two vendors.
- What to Check in an AI Vendor's Data Processing Agreement — What the data processing agreement itself should say.
- What If Your AI Vendor Shuts Down? Checks Before You Commit — Continuity checks for smaller or newer vendors.
- How to Check an AI Software Vendor's Customer References — How to get honest answers from a vendor's reference customers.
- AI Washing: How to Spot Software That Oversells Its AI — Signs the AI in the pitch is thinner than the demo suggests.
- What Uptime and Support Should an AI Vendor Promise You? — What uptime and response times to ask for in writing.
- How to Negotiate AI Software Prices and Seat Numbers — Use the answers you collect to negotiate price and seats.
- What to Ask an AI Chatbot Vendor Before You Sign Up — Extra questions when the tool will talk to your customers.
- How to Evaluate an AI Implementation Proposal or Quote — A 22-point checklist for any AI implementation quote, with the phrases to pin down, a scoring sheet and two quotes compared over three years.
- AI Tool Approval Process: How Staff Request a New AI Tool — The request form staff fill in, the checklist the reviewer works through, and the three replies, so new AI tools get approved in days, not months.
- What to Do Before You Buy Any AI Tool: A 10-Point Checklist — Ten checks to run before paying for any AI tool, from pricing the job it replaces to reading the exit terms, with a kitchen-fitter worked example.
- What Is an API? Why It Matters When You Buy Software — A plain-English explanation of APIs for people buying software, with the vendor questions and pricing traps that decide whether tools can connect.
- Restaurant AI Tools: 12 Questions to Ask Before You Sign Up — Twelve written questions for any restaurant AI vendor, with red flags, a scoring sheet and five test calls to make before you commit.
- Hotel AI Guest Messaging Tools Compared for Independent Properties — HiJiffy, Duve, Canary, Asksuite, Akia and built-in PMS messaging compared for independent hotels, with a worked choice and ten test messages.
- AI Booking Systems for Appointment Businesses: What to Check — A 24-point checklist for choosing an AI booking system, grouped by risk, with how to verify each item and a two-hour test script to run before you sign.
- AI Screening: Bolt It Onto Your ATS or Switch Systems? — Bolt-on, upgrade or switch: how a small agency decides on AI screening, with switching costs worked through and a 30-day trial log to copy.
- Questions to Ask Before Buying AI That Touches Client Data — Nineteen questions to put to any AI vendor before client files go in, with what a good answer looks like and the replies that should stop a purchase.
- What to Ask Before Buying Any AI Tool for a Medical Practice — A grouped checklist of questions for any AI vendor selling to a medical practice, what a good answer looks like, a scored example and the red-flag answers.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: ISO page for ISO/IEC 42001:2023; public coverage of OpenAI's Copyright Shield terms for ChatGPT Enterprise and API customers; vendor trust and pricing pages checked 27 September 2026.